CVE-2026-104725
Published 10 October 2026 · tracked since 10 October 2026
Description
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter within the `process_edit()` function, which allows any auth
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-105885 HIGH 8.8
- CVE-2026-91136 HIGH 7.5
- CVE-2026-96662 HIGH 7.5
- CVE-2026-93945 CRITICAL 9.8
- CVE-2026-93936 CRITICAL 9.8
- CVE-2026-93937 CRITICAL 9.8
- CVE-2026-93938 CRITICAL 9.8
- CVE-2026-93940 CRITICAL 9.8
- CVE-2026-93941 CRITICAL 9.8
- CVE-2026-93942 CRITICAL 9.8